zhuguanyu Please add the Basic info of the k8s cluster you have deployed on UNH Lab including the version and config file.
...
functest-kubernetes-healthcheck
zip_campaign
...
stage
...
job
...
result
detail
...
functest-kubernetes-healthcheck
...
k8s_quick
...
PASS
...
...
PASS
...
functest-kubernetes-benchmarking
...
netperf
...
PASS
...
xrally_kubernetes_full
...
PASS
...
kube_bench_master
...
PASS
...
kube_bench_node
...
PASS
...
kube_hunter
...
PASS
...
title | WARNING |
---|
2022-11-10 11:20:38,300 - xtesting.ci.run_tests - INFO - Deployment description:
+-------------------------+----------------------------------------------------------+
| ENV VAR | VALUE |
+-------------------------+----------------------------------------------------------+
| CI_LOOP | daily |
| DEBUG | false |
| DEPLOY_SCENARIO | k8-nosdn-nofeature-noha |
| INSTALLER_TYPE | unknown |
| BUILD_TAG | |
| NODE_NAME | |
| TEST_DB_URL | http://testresults.opnfv.org/test/api/v1/results |
| TEST_DB_EXT_URL | |
| S3_ENDPOINT_URL | |
| S3_DST_URL | |
| HTTP_DST_URL | |
+-------------------------+----------------------------------------------------------+
2022-11-10 11:20:38,316 - xtesting.ci.run_tests - INFO - Loading test case 'kube_hunter'...
2022-11-10 11:20:38,823 - xtesting.ci.run_tests - INFO - Running test case 'kube_hunter'...
2022-11-10 11:21:07,061 - functest_kubernetes.security.security - WARNING - Skipping CAP_NET_RAW Enabled (severity is configured as high)
2022-11-10 11:21:07,061 - functest_kubernetes.security.security - WARNING - Skipping Read access to pod's service account token (severity is configured as high)
2022-11-10 11:21:07,062 - functest_kubernetes.security.security - WARNING - Skipping Access to pod's secrets (severity is configured as high)
2022-11-10 11:21:07,062 - functest_kubernetes.security.security - WARNING - Skipping K8s Version Disclosure (severity is configured as high)
2022-11-10 11:21:07,062 - functest_kubernetes.security.security - WARNING - Skipping Access to API using service account token (severity is configured as high)
2022-11-10 11:21:07,064 - functest_kubernetes.security.security - WARNING -
+--------------------------------+----------------------------------------------------+------------------+
| CATEGORY | VULNERABILITY | SEVERITY |
+--------------------------------+----------------------------------------------------+------------------+
| Access Risk | CAP_NET_RAW Enabled | low |
| Access Risk | Read access to pod's service account token | low |
| Access Risk | Access to pod's secrets | low |
| Information Disclosure | K8s Version Disclosure | medium |
| Information Disclosure | Access to API using service account token | medium |
+--------------------------------+----------------------------------------------------+------------------+
2022-11-10 11:21:07,074 - xtesting.ci.run_tests - INFO - Test result:
+---------------------+------------------+------------------+----------------+
| TEST CASE | PROJECT | DURATION | RESULT |
+---------------------+------------------+------------------+----------------+
| kube_hunter | functest | 00:28 | PASS |
+---------------------+------------------+------------------+----------------+
...